OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63045

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

The Apache HTTP Server versions up to 2.4.68 are vulnerable due to improper validation of FTP PASV reply addresses in the mod_proxy_ftp module, allowing untrusted FTP servers to redirect data connections to arbitrary third-party hosts. This vulnerability poses a risk of unauthorized data exposure and potential exploitation in forward proxy configurations. Organizations using affected versions should prioritize upgrading to version 2.4.69 to mitigate these risks.

CVE
CVE-2026-63045
Severity
HIGH
CVSS
7.5
EPSS
0.33%
Apache

Original NVD Description

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)